This Privacy Policy explains how NEURAL CRAFT LIMITED handles information for OhMyStar (“OhMyStar”, “the app”, “we”, “us”, or “our”). OhMyStar is a native macOS app for organizing, searching, and revisiting GitHub starred repositories.
This policy is specific to the OhMyStar 3.0 codebase currently being prepared for release. As of the date above, the Mac App Store still distributes version 2.2.8. The current App Store listing and its App Privacy disclosure remain the applicable store disclosure for that public build and may describe different diagnostics practices. This Version 3 policy is not a retroactive description of version 2.2.8.
The broader OhMyApps website, contact forms, and support channels are covered by the general OhMyApps Privacy Policy.
Summary
- OhMyStar uses your GitHub account; it does not create a separate OhMyStar account.
- The Version 3 app requests GitHub’s
public_repoOAuth scope so it can load public repository information and manage your stars. - GitHub account fields, the OAuth token, starred repository metadata, tags, settings, and caches are stored locally on your Mac.
- OhMyStar Pro can perform manual, user-initiated tag-data transfer through your private Apple CloudKit database.
- The public Trending service receives the selected language and time range, plus standard network request information handled by Cloudflare. It does not receive your GitHub OAuth token, local tags, or GitHub profile.
- The audited Version 3 build does not include active third-party advertising, analytics, or cross-app tracking SDKs.
- Optional diagnostic files are disabled by default, stay on your Mac, and are not uploaded automatically.
GitHub Authorization and Account Information
OhMyStar uses GitHub OAuth Device Flow. The app requests a one-time device and user code from GitHub, opens GitHub in your browser, and polls GitHub until you approve, deny, cancel, or let the code expire. If you choose to continue, the one-time user code is copied to the macOS clipboard so you can paste it into GitHub.
The Version 3 app requests GitHub’s public_repo scope. GitHub presents the authorization and controls the permission grant. OhMyStar currently uses the resulting token to:
- load your GitHub profile and starred-repository count;
- fetch your starred public repositories and their metadata;
- fetch rendered README content;
- star or unstar a public repository; and
- use GitHub Search as a fallback when the primary Trending service is unavailable.
GitHub may return account information such as your numeric GitHub user ID, login, name, email address if available to the app, avatar URL, profile URL, follower and following counts, and starred-repository count. OhMyStar stores these fields and the OAuth token in its local app data so it can keep you signed in and maintain the correct library.
The user OAuth token is sent to GitHub for authenticated API requests. It is not sent to the OhMyStar Trending service or intentionally uploaded to a NEURAL CRAFT LIMITED server.
Signing out of OhMyStar clears the saved OAuth token from the active local login record. It does not revoke the authorization at GitHub and does not erase the local repository library. You can review or revoke OAuth access from your GitHub application settings.
GitHub handles authorization, API requests, account information, and repository content under the GitHub Privacy Statement.
Information Stored on Your Mac
Depending on the features you use, OhMyStar may store:
- GitHub account fields and the OAuth token described above;
- starred public-repository identifiers, names, owners, descriptions, language, dates, links, star counts, fork counts, and related public metadata;
- your custom tag names and tag-to-repository relationships;
- cached README HTML, remote images, repository avatars, and Trending results;
- appearance, language, keyboard shortcut, launch-at-login, cache, and diagnostic-log preferences;
- local OhMyStar Pro entitlement and expiration state received from Apple; and
- temporary import, export, and operation state needed to complete actions you start.
This information is stored in the app’s local sandbox, databases, preferences, and cache folders. Local storage lets the app reopen your library and show previously fetched information, but live refresh, authorization, star actions, purchases, Cloud Data, remote images, and Trending require network access.
The app’s Clear All cache control removes the image cache, README cache, and local diagnostic log files. It does not erase the main repository library or revoke GitHub access.
Import and Export
OhMyStar can import organization data from an OhMyStar JSON backup, an Astral JSON export, or an OhMyStar 1.x backup. Imported data may contain a GitHub numeric user ID, tag names, and repository identifiers. The app validates the selected file and merges supported tag relationships into the current local library.
When you export, OhMyStar creates a readable JSON file containing the current GitHub numeric user ID, tag names, and repository identifiers. You choose the destination. Exported files are outside the app’s control and may not be encrypted, so you are responsible for storing, sharing, and deleting them safely.
Legacy Share-Link Import
The normal Version 3 interface hides the old OhMyStar sharing feature, but the app still registers the legacy ohmystar://import link type for compatibility. If you open one of these links and then confirm the import prompt, the app sends the share identifier to the legacy ohmystarapp.com service to retrieve a list of public repository names. The service may receive the identifier and standard network request information.
After you confirm, OhMyStar can use your GitHub authorization to star those repositories, reload your starred library, and optionally attach the imported tag. Opening or cancelling the prompt does not by itself complete the import. Only use a legacy share link from a source you trust, and review the resulting GitHub stars afterward.
Optional OhMyStar Pro Cloud Data
Cloud Data is an optional OhMyStar Pro feature. It is manual rather than continuous background sync. When you explicitly choose a Cloud Data action, the app uses Apple’s private CloudKit database associated with your Apple Account.
Cloud records contain:
- your numeric GitHub user ID, used to separate organization data for different GitHub accounts;
- tag names; and
- GitHub repository identifiers attached to those tags.
The Cloud Data records do not contain your GitHub OAuth token, GitHub email address, complete local repository metadata, README cache, diagnostic logs, or exported backup files.
The available actions have different effects:
- Download imports cloud tag relationships into the current local library.
- Merge combines local and cloud tag relationships, then downloads the result.
- Replace makes the cloud tag snapshot match the current Mac’s local tag organization.
- Delete Cloud Data removes matching OhMyStar tag records from iCloud but does not delete data stored on this Mac, revoke GitHub access, or cancel purchases.
Apple processes Apple Account, CloudKit, App Store, and platform information under the Apple Privacy Policy.
Trending Service
OhMyStar Version 3 uses a public Cloudflare Worker operated for OhMyStar to retrieve and cache public GitHub Trending results. A Trending request contains the selected daily, weekly, or monthly range and, when chosen, a programming-language filter.
The service does not require an OhMyStar account and does not receive the GitHub OAuth token, local repository library, local tags, or GitHub profile from the app. It caches public repository snapshots by language and time range so many users can reuse the same result. Public snapshots may remain in the service cache for up to 14 days.
As with most internet services, Cloudflare may process standard request and operational information such as IP address, routing data, request time, endpoint, response status, and service errors for delivery, security, reliability, and observability. Cloudflare handles that information under its Privacy Policy.
If the Trending service is unavailable, the app may send an authenticated repository-search request directly to GitHub instead.
README Content, Images, and External Links
OhMyStar requests rendered README content from GitHub. README files can include images or other media hosted by GitHub or third-party domains. Loading those resources can send standard network information, such as your IP address and request headers, to the resource host. Those hosts have their own terms and privacy practices.
User-activated web, repository, homepage, and mail links open through macOS or your default browser. Activity after a link opens is handled by the destination, browser, and macOS rather than by OhMyStar.
App Store Purchases
OhMyStar may offer optional monthly and yearly Pro subscriptions and may recognize an eligible legacy OhMyStar upgrade through Apple StoreKit.
Apple processes payment details, billing, tax, renewal, cancellation, refund, purchase history, and App Store account information. OhMyStar receives product information and verified transaction or entitlement status needed to show prices, complete purchases, restore access, and determine whether Pro is active. The app stores the resulting Pro state and expiration date locally. NEURAL CRAFT LIMITED does not receive your full payment card number through OhMyStar.
Diagnostics and Analytics
The audited Version 3 build does not contain active third-party advertising, analytics, or cross-app tracking SDKs. Its app privacy manifest declares no tracking and no app-collected data types, but that manifest does not replace the need to maintain an accurate App Store privacy disclosure for the released binary.
OhMyStar can write diagnostic log files to your Mac if you explicitly enable Write diagnostic logs to disk and then relaunch the app. These files can contain app and device context, file paths, operation details, and error messages. Logging is disabled by default. Files are not uploaded automatically, and the app’s cache-clearing control removes them. Review a diagnostic file before choosing to send it to support.
Apple may separately provide crash or usage diagnostics if you enabled Apple’s device-level sharing settings. Apple controls that collection and sharing.
Support and Voluntary Communications
If you contact us, we receive the information you choose to provide, such as your email address, message, screenshots, exported diagnostics, or device and app details. We use it to respond, troubleshoot, protect the service, and comply with legal obligations. Do not send your GitHub OAuth token, passwords, payment-card details, or other secrets.
Sharing and Disclosure
The audited Version 3 code contains no active advertising or cross-app tracking SDK and no app flow that sends the local library to an advertising network. This technical statement is limited to the Version 3 app code and does not describe information you independently send through the OhMyApps website or a support channel.
Information may be processed or disclosed:
- to GitHub, Apple, Cloudflare, remote README resource hosts, and destinations you intentionally open, as described above;
- to the legacy
ohmystarapp.comimport service only after you open and confirm a compatible share link; - to a support destination when you intentionally send a message, screenshot, export, or diagnostic file; or
- when NEURAL CRAFT LIMITED is legally required to disclose information it actually holds or must act to protect users, providers, rights, or service security.
Retention and Your Controls
- Local library data remains on your Mac until you remove the relevant app data. Signing out alone does not delete it.
- Image, README, and diagnostic-log caches remain until they expire, are replaced, or you use the cache-clearing control.
- The OAuth token remains locally available until you sign out, the local record is removed, or GitHub revokes it.
- Private CloudKit tag records remain until you replace or delete them, remove app data through Apple controls, or Apple removes them under its policies.
- Exported backups remain wherever you save or copy them.
- Public Trending snapshots may be cached for up to 14 days. Operational request data is retained according to service, security, legal, and Cloudflare requirements.
- Support communications are retained as long as reasonably needed to respond, maintain records, resolve disputes, enforce agreements, and meet legal obligations.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection for personal information controlled by NEURAL CRAFT LIMITED. We may need to verify your request. Data controlled directly by GitHub, Apple, Cloudflare, a remote content host, or another destination must generally be managed through that provider.
Security
OhMyStar uses Apple’s app sandbox, HTTPS service connections, GitHub Device Flow, and private CloudKit storage for the relevant features. Its local Realm database is configured with file encryption, but that protection is not described as device-bound or end-to-end encryption. No local storage, network transfer, cloud service, or software can be guaranteed completely secure.
Keep your Mac account secure, review GitHub authorizations, protect exported files, and never share OAuth tokens or passwords.
International Processing
GitHub, Apple, Cloudflare, remote content hosts, the legacy import service, and any support destination you choose may process information in countries other than your own. Their privacy policies and service terms describe the practices they control.
Children’s Privacy
OhMyStar is a general developer tool and is not directed to children. GitHub and Apple account eligibility rules also apply. We do not knowingly use OhMyStar Version 3 to collect personal information from children for advertising or profiling. If you believe a child has sent personal information through support, contact us so we can review the request.
Changes to This Policy
We may update this Privacy Policy when OhMyStar, its release status, requested GitHub permissions, local storage, Cloud Data, purchases, diagnostics, or service providers change. We will update the “Last updated” date and provide additional notice where required.
Contact
Questions or privacy requests can be sent to NEURAL CRAFT LIMITED through the OhMyApps contact page or by email at yu@ohmyapps.com.